Reverse proxy and security..

Currently reading
Reverse proxy and security..

73
23
NAS
DS920+
Operating system
  1. Windows
Mobile operating system
  1. Android
Hello all,

Something been on my mind for quite a while is security, security and security!
I currently have my RaPi 4 with my home assistant exposed a on a single port, currently the only thing exposed but I would like to expose my OpenVPN as well. Just a few questions:

1) Would it be wise to expose my NAS to the WWW and run reverse proxy on that and then direct traffic to OpenVPN and HA appropriately via 2 subdomains?
2) Where is a cheap but reliable place in the UK to buy a domain name that allows SSL and subdomains so I don't need to rely on DDNS/DuckDNS/NoIP etc?
3) With OpenVPN, how is that more secure by connecting to that then opening my NAS compared to just having a specific port for what I need open? Is it just another layer or does it actually add some security (apologies for the very stupid question!) ?
 
1) as long as you have it hardened enough why not

2) Dreamhost? Cloudflare as well

3) it depends what system is on a custom port. With vpn you always have to authenticate, you can dictate encryption being used. On the other hand it depends also do you mean incoming or outgoing vpn in this case?
 
To extend point 03) VPN Solutions are widely used and designed for security - usualy you have two-way tls auth when the connection is establishing, before you even enter the credentials. I am not sure if it would be a fair comparison with a website/portal that can be miss configured or even run potentialy exploitable code,
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

Fair enough I was coming to that conclusion myself and that'd cost I guess.
Replies
4
Views
1,591
  • Question
You are right - using :443 worked, and with 2FA, which was my initial issue. Thanks! This doesn't work...
Replies
9
Views
2,990
Try adding them one-at-a-time, saving, logging out, restarting* your computer, then logging back in until...
Replies
12
Views
1,089
I receive the reports monthly, just actually got them on 2/1 and verified for some reason this is still...
Replies
4
Views
642
It took a while to get iOS Syno Drive Client to reset and ask for my 2FA to log back in. It was set up...
Replies
2
Views
494
  • Question
Unless your home network is CGNAT, Tailscale offers no real advantage over VPN or HTTPS. Keep it simple...
Replies
3
Views
1,265

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Back
Top